Threats Tagged 'cyberespionage'
View all threats tagged with 'cyberespionage'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cyberespionage'
Click on any threat for detailed analysis and mitigation recommendations
0 ESET researchers uncovered a Lazarus attack against a Spanish aerospace company where attackers masqueraded as Meta recruiters on LinkedIn, sending trojanized coding challenges to employees. The campaign deployed multiple tools including LightlessCan, a previously undocumented backdoor that mimics native Windows commands to evade detection. Initial access was achieved through spearphishing via LinkedIn Messaging, delivering malicious executables disguised as C++ programming tests. The attack chain involved DLL side-loading techniques delivering payloads including NickelLoader downloader, miniBlindingCan variant, and the sophisticated LightlessCan RAT supporting 68 commands. LightlessCan represents a significant advancement over its predecessor BlindingCan, implementing execution guardrails and enhanced stealth capabilities. The campaign targeted aerospace technology and know-how for cyberespionage purposes, consistent with North Korean strategic objectives in missile development. Join the discussion | AlienVault OTX General | 09/18/2026, 21:29:42 UTC Added: 09/21/2026, 08:46:37 UTC |
ESET researchers have documented SparroWocky, a sophisticated C++ backdoor deployed by the FamousSparrow APT group since August 2025. This China-aligned threat actor has shifted focus to extensively targeting governmental organizations across Latin America, likely in response to increased US interest in the region. SparroWocky replaced the group's previous SparrowDoor backdoor and demonstrates advanced capabilities including reflective loading, anti-analysis techniques like SilentMoonwalk for call stack spoofing, and the ability to execute Beacon Object Files. The modular backdoor incorporates open-source projects directly into its codebase, uses TLS-encrypted communications with RC4 encryption for data exfiltration, and employs sophisticated evasion methods including MinHook API hooking and custom PE loading with host process camouflage. The targeting pattern reflects China's strategic interest in monitoring Latin American governmental responses to current US pressures regarding investments and infrastruc... Join the discussion | AlienVault OTX General | 09/17/2026, 16:19:02 UTC Added: 09/18/2026, 08:46:41 UTC |
0 During a targeted intrusion investigation in June 2026, investigators uncovered GoCaracal, a previously undocumented modular framework written in Go. This sophisticated toolkit exists in two operational profiles: a lightweight implant for establishing access and delivering payloads, and an extended build for sustained intelligence collection with capabilities including keylogging, browser credential theft, WebRTC remote desktop, and SOCKS5 proxying. Analysis of 249 samples traced the framework's evolution from January to July 2026, revealing active development and maturation. A notable innovation includes an Ethereum smart-contract fallback mechanism enabling operators to update C2 infrastructure without redeploying malware. The activity targeted a Venezuelan communications organization using Spanish-language financial lures, weaponized SVG files, and delivery methods consistent with established tradecraft. GoCaracal was deployed alongside an updated Bandook variant, suggesting the new framework currently ... Join the discussion | CVE Database V5 | 08/26/2026, 17:18:24 UTC Added: 06/02/2026, 19:52:44 UTC |
SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security. Join the discussion | AlienVault OTX General | 08/20/2026, 07:04:46 UTC Added: 08/20/2026, 08:22:26 UTC |
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers. Join the discussion | CVE Database V5 | 07/23/2026, 16:25:23 UTC Added: 01/05/2026, 15:03:11 UTC |
Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure. Join the discussion | AlienVault OTX General | 07/21/2026, 11:19:50 UTC Added: 07/22/2026, 08:22:06 UTC |
Between February 2024 and April 2026, multiple cyberespionage actors, suspected to be China-nexus and India-nexus threat groups, conducted sustained intrusions into Pakistani law enforcement organizations, particularly Balochistan Police. The compromised infrastructure included network appliances and servers hosting web applications managing criminal records, biometric data, hotel registrations, and citizen complaints. A suspected China-nexus actor weaponized the Complaint Management System web application by deploying custom implants disguised as portal updates, targeting both police personnel and citizens. China's likely motivation stems from concerns over the safety of Chinese nationals in Pakistan, particularly regarding attacks by separatist groups. India's suspected interest relates to its adversarial relationship with Pakistan, with Balochistan Police offering intelligence on security operations in a strategically sensitive province. The attackers deployed PlugX, ShadowPad, Cobalt Strike, Remcos, an... Join the discussion | AlienVault OTX General | 07/09/2026, 22:16:04 UTC Added: 07/10/2026, 07:47:32 UTC |
This analysis examines Gamaredon's (UAC-0010, Armagedon) advanced espionage operations targeting Ukrainian government, military, and critical infrastructure. The FSB-operated group deploys GammaSteel, a sophisticated stealer operating almost entirely from memory using Windows DPAPI encryption and storing 71 distinct payload functions in the HKCU\Printers registry key. The malware employs three concurrent data acquisition mechanisms: timed drive scans, USB monitoring for air-gapped systems, and real-time file surveillance. Exfiltration occurs via legitimate S3-compatible cloud storage (Tebi.io) with fallback to operator-controlled servers. The infection chain extensively uses VBScript for evasion, Dead Drop Resolvers on platforms like Telegram and Mastodon for C2 configuration, and includes bidirectional backdoor capabilities enabling arbitrary remote code execution. Infrastructure demonstrates high automation with servers rotated approximately every 24 hours. Join the discussion | AlienVault OTX General | 06/04/2026, 13:57:26 UTC Added: 06/05/2026, 08:49:15 UTC |
MuddyWater, an Iran-aligned cyberespionage group, has been targeting critical infrastructure in Israel and Egypt with custom malware and improved tactics. The campaign uses previously undocumented tools like the Fooder loader and MuddyViper backdoor to enhance defense evasion and persistence. Fooder masquerades as a Snake game and uses game-inspired techniques to hinder analysis. MuddyViper enables system information collection, file manipulation, and credential theft. The group also employs browser-data stealers and reverse tunneling tools. This campaign demonstrates MuddyWater's evolution towards more sophisticated and refined approaches, though traces of operational immaturity remain. The group continues to pose a significant threat, particularly to government, military, telecommunications, and critical infrastructure sectors in the Middle East. Join the discussion | AlienVault OTX General | 01/03/2026, 11:05:58 UTC Added: 01/05/2026, 11:18:20 UTC |
ESET researchers have uncovered a new China-aligned APT group named LongNosedGoblin targeting governmental entities in Southeast Asia and Japan for cyberespionage. The group employs a varied custom toolset of C#/.NET applications and abuses Group Policy for lateral movement. Key tools include NosyHistorian for collecting browser history, NosyDoor backdoor using cloud services as C&C, and NosyStealer for exfiltrating browser data. The attackers also utilize techniques like AppDomainManager injection and AMSI bypassing. LongNosedGoblin has been active since at least September 2023, showing ongoing campaigns throughout 2024 and 2025. The research provides detailed analysis of the group's malware and tactics, including potential sharing of the NosyDoor backdoor among multiple China-aligned actors. Join the discussion | AlienVault OTX General | 01/03/2026, 11:05:57 UTC Added: 01/05/2026, 11:18:20 UTC |
Showing 1 to 10 of 20 results